Show Filters

Top Results

NERC CIP Program Recovery

Full Program Turnaround

Achieved zero regulatory findings during follow-up NERC CIP audit

Comprehensive Workforce Development

Trained and engaged more than 120 employees across compliance, engineering, cybersecurity, and operations to create a more sustainable program

Program Durability

Enabled self-sustaining compliance readiness by embedding recurring tasks into a work management tool and deploying structured job plans and training across the organization

Challenge

A large electric utility received an unfavorable audit that pointed to a significant programmatic breakdown and a lack of cultural understating of NERC CIP standards. Significant gaps existed in the organization’s roles and responsibilities to provide governance and oversight for the standards, procedures were not well maintained or did not exist, and the organization relied on manual methods to document and collect evidence. Operating and technical groups did not understand the NERC CIP standards, requirements, or the implications of not complying. Enterprise and business unit leadership were facing tight timelines to respond to audit findings and a situation where repeat issues would not be tolerated by the regulator or the board.

Process

  • Established an operating model and organization for the NERC CIP standards​
  • Developed and updated NERC CIP documentation, including seven technical program documents, 11 new CIP procedures, and more than seven updated procedures​
  • Developed more than 25 PMs and entered them into Maximo work management tool for recurring CIP requirements; allowed management visibility to oversee on-going CIP tasks​
  • Developed eight template job plans with work instructions​
  • Prepared and issued computer-based awareness training for more than 800 workers, totaling more than 1,200 courses completed​
  • Delivered CIP technical instructor-led training at medium-impact facilities, providing direct training to more than 350 workers​
  • Provided initial training to compliance managers and compliance analysts​
  • Worked with operational leaders to self-certify they knew how to execute work

Result

  • Next NERC CIP regulatory audit contained zero findings for the business unit​
  • Developed the program in a way that engaged more than 120 employees, and the entire organization (compliance, engineering, cybersecurity and operations) was able to self-sustain the program

Related Insights

Let’s Work Together

We don’t solve problems with canned methodologies; we help you solve the right problem in the right way. Our experience ensures that the solution works for you.